PT-2024-1603 · Linux+5 · Linux Kernel+5

白家驹

·

Published

2024-02-04

·

Updated

2025-01-24

·

CVE-2024-24858

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.28
Description A race condition was found in the Linux kernel's net/bluetooth in the {conn,adv} {min,max} interval set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.
Recommendations For Linux kernel versions prior to 6.6.28, update to version 6.6.28 or later to resolve the issue. As a temporary workaround, consider restricting access to the {conn,adv} {min,max} interval set() function until a patch is available.

Exploit

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10855
AZL-34882
BDU:2024-01194
CVE-2024-24858
DLA-3840-1
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_9315
MGASA-2024-0141
MGASA-2024-0142
OESA-2024-1617
OESA-2024-1618
OESA-2025-1080
OESA-2025-1081
RHSA-2024:9315
RHSA-2024_9315
USN-6893-1
USN-6893-2
USN-6893-3
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6922-1
USN-6922-2
USN-6926-1
USN-6926-2
USN-6926-3
USN-6927-1
USN-6938-1
USN-7019-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Ubuntu